[pkix] Re: [Technical Errata Reported] RFC5272 (8137 )

Deb Cooley <[email protected]> Tue, 29 Oct 2024 11:41:09 -0400
Newsgroups gmane.ietf.x509
Message-ID <CAGgd1OdJjPFDrK1gU_Phow_-z-HomBBHFQZeUHAE_S7i1UPjVA@mail.gmail.com>
--===============8117023751514057194==
Content-Type: multipart/alternative; boundary="00000000000003561f06259f6b1e"

--00000000000003561f06259f6b1e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

opinions?

Deb

On Sat, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System <rfc-editor@rfc-e=
ditor.org>
wrote:

> The following errata report has been submitted for RFC5272,
> "Certificate Management over CMS (CMC)".
>
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid8137
>
> --------------------------------------
> Type: Technical
> Reported by: David von Oheimb <[email protected]>
>
> Section: C.1
>
> Original Text
> -------------
> NoSignatureValue contains the hash of the certification request.
>
> Corrected Text
> --------------
> NoSignatureValue contains the SHA-1 hash value of the certification
> request.
> The hash value given by NoSignatureValue SHOULD be ignored.
>
> Notes
> -----
> The hash value was not sufficiently defined because the choice of the has=
h
> algorithm was not specified.
> At that time presumably the use of SHA-1 was implied.
>
> I suggest requiring SHA-1 here simply for backward compatibility.
> From today's perspective more flexibility may be demanded and SHA-1 likel=
y
> no more is the best choice.
>
> Anyway I see no real value in NoSignatureValue (pun intended), so it
> should not matter.
> For this reason I propose ignoring the hash value.
>
> Instructions:
> -------------
> This erratum is currently posted as "Reported". (If it is spam, it
> will be removed shortly by the RFC Production Center.) Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party
> will log in to change the status and edit the report, if necessary.
>
> --------------------------------------
> RFC5272 (draft-ietf-pkix-2797-bis-07)
> --------------------------------------
> Title               : Certificate Management over CMS (CMC)
> Publication Date    : June 2008
> Author(s)           : J. Schaad, M. Myers
> Category            : PROPOSED STANDARD
> Source              : Public-Key Infrastructure (X.509)
> Stream              : IETF
> Verifying Party     : IESG
>

--00000000000003561f06259f6b1e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>opinions?</div><div><br></div><div>Deb<br></div></div=
><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Sa=
t, Oct 12, 2024 at 6:36=E2=80=AFAM RFC Errata System &lt;<a href=3D"mailto:=
[email protected]">[email protected]</a>&gt; wrote:<br></di=
v><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;borde=
r-left:1px solid rgb(204,204,204);padding-left:1ex">The following errata re=
port has been submitted for RFC5272,<br>
&quot;Certificate Management over CMS (CMC)&quot;.<br>
<br>
--------------------------------------<br>
You may review the report below and at:<br>
<a href=3D"https://www.rfc-editor.org/errata/eid8137" rel=3D"noreferrer" ta=
rget=3D"_blank">https://www.rfc-editor.org/errata/eid8137</a><br>
<br>
--------------------------------------<br>
Type: Technical<br>
Reported by: David von Oheimb &lt;<a href=3D"mailto:David.von.Oheimb@siemen=
s.com" target=3D"_blank">[email protected]</a>&gt;<br>
<br>
Section: C.1<br>
<br>
Original Text<br>
-------------<br>
NoSignatureValue contains the hash of the certification request. <br>
<br>
Corrected Text<br>
--------------<br>
NoSignatureValue contains the SHA-1 hash value of the certification request=
. <br>
The hash value given by NoSignatureValue SHOULD be ignored.<br>
<br>
Notes<br>
-----<br>
The hash value was not sufficiently defined because the choice of the hash =
algorithm was not specified.<br>
At that time presumably the use of SHA-1 was implied.<br>
<br>
I suggest requiring SHA-1 here simply for backward compatibility.<br>
>From today&#39;s perspective more flexibility may be demanded and SHA-1 lik=
ely no more is the best choice.<br>
<br>
Anyway I see no real value in NoSignatureValue (pun intended), so it should=
 not matter.<br>
For this reason I propose ignoring the hash value.<br>
<br>
Instructions:<br>
-------------<br>
This erratum is currently posted as &quot;Reported&quot;. (If it is spam, i=
t <br>
will be removed shortly by the RFC Production Center.) Please<br>
use &quot;Reply All&quot; to discuss whether it should be verified or<br>
rejected. When a decision is reached, the verifying party=C2=A0 <br>
will log in to change the status and edit the report, if necessary.<br>
<br>
--------------------------------------<br>
RFC5272 (draft-ietf-pkix-2797-bis-07)<br>
--------------------------------------<br>
Title=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: Certificate M=
anagement over CMS (CMC)<br>
Publication Date=C2=A0 =C2=A0 : June 2008<br>
Author(s)=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0: J. Schaad, M. Myers<br>
Category=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : PROPOSED STANDARD<br>
Source=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : Public-Key Infrast=
ructure (X.509)<br>
Stream=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 : IETF<br>
Verifying Party=C2=A0 =C2=A0 =C2=A0: IESG<br>
</blockquote></div>

--00000000000003561f06259f6b1e--


--===============8117023751514057194==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KcGtpeCBtYWls
aW5nIGxpc3QgLS0gcGtpeEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IHBraXgtbGVhdmVAaWV0Zi5vcmcK

--===============8117023751514057194==--